security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly have unspecified other impact via a crafted application that uses the big_key data type.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Nov 28, 2016 |
| Ubuntu | — | Upgrade linux-image-powerpc64-embUpgrade linux-image-raspi2Upgrade linux-image-4.8.0-32-powerpc64-embUpgrade linux-image-powerpc-e500mcUpgrade linux-image-genericUpgrade linux-image-4.8.0-32-generic-lpaeUpgrade linux-image-4.8.0-32-powerpc-smpUpgrade linux-image-powerpc-smpUpgrade linux-image-generic-lpaeUpgrade linux-image-4.8.0-32-genericUpgrade linux-image-4.8.0-1021-raspi2Upgrade linux-image-4.8.0-32-lowlatencyUpgrade linux-image-4.8.0-32-powerpc-e500mcUpgrade linux-image-lowlatency | Dec 21, 2016 | Nov 27, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub